LeakBase 24Kk ULP by firegoon
We noticed an unusual surge in activity on a well-known underground forum on June 21, 2024, coinciding with the public appearance of a stealer log identified as "24Kk ULP." What struck us immediately was the sheer volume of unique email addresses and, more critically, the presence of plaintext passwords within the dataset. This isn't just another credential stuffing fodder; the direct accessibility of these credentials presents a clear and present danger to the users whose data has been compromised. The context of this leak, originating from a stealer, suggests a compromise of user endpoints rather than a direct database exfiltration from a single entity.
The "24Kk ULP" stealer log, discovered on June 21, 2024, contained approximately 25 million individual records, of which 2,279,023 were unique email addresses. The data exfiltrated includes not only these email addresses but also plaintext passwords and associated HomePage URLs. This combination is particularly concerning, as it provides attackers with direct access credentials and potential context about the user's online presence. The source structure points towards compromised user devices, where stealer malware likely harvested credentials from browsers and other applications. The leak location on a prominent hacking forum indicates immediate intent for exploitation, likely through credential stuffing attacks against other services or direct account takeovers.
While specific news coverage for this particular "24Kk ULP" stealer log is nascent, the modus operandi aligns with ongoing trends in credential harvesting. Research from cybersecurity firms consistently highlights the prevalence of stealer malware as a primary vector for obtaining large volumes of user credentials. For instance, reports from Mandiant and CrowdStrike have detailed the increasing sophistication of stealer operations, which often result in data dumps appearing on forums like the one where this log was found. The presence of plaintext passwords, a recurring theme in these types of leaks, continues to be a significant vulnerability, enabling widespread account compromise across various platforms.
Breach Breakdown
2,279,023 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds